Gunet maintains the Open eClass platform, an educational learning management system that serves academic and institutional deployments across multiple regions. The vendor's vulnerability footprint, despite a narrow product portfolio, reflects prominence within its educational sector and concentrates on application-layer weaknesses including cross-site scripting, improper access control, sensitive information disclosure, and insufficient session management. These weakness classes are typical of web-facing educational platforms and arise from the intersection of authentication, user data handling, and web-interface design that characterizes learning management systems. Defenders deploying Open eClass should prioritize input validation and session-security controls; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gunet over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-37113HIGH GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP, an attacker can upload a web | Feb 3, 2026 | 8.8 | 27 | NO | NO |
CVE-2020-37116HIGH GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploadin | Feb 3, 2026 | 8.8 | 25 | NO | NO |
CVE-2026-24669HIGH The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an insecure password reset mechanism allows local attackers | Feb 3, 2026 | 7.8 | 23 | NO | NO |
CVE-2021-44266MEDIUM GUnet Open eClass (aka openeclass) before 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter. | Jun 11, 2022 | 6.1 | 23 | NO | NO |
CVE-2020-24381HIGH GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks d | Aug 19, 2020 | 7.5 | 23 | NO | NO |
CVE-2026-24773HIGH The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an Insecure Direct Object Reference (IDOR) vulnerability all | Feb 3, 2026 | 7.5 | 22 | NO | NO |
CVE-2026-24670MEDIUM The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated s | Feb 3, 2026 | 6.5 | 20 | NO | NO |
CVE-2026-24668MEDIUM The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated s | Feb 3, 2026 | 6.5 | 20 | NO | NO |
CVE-2026-24666MEDIUM The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Cross-Site Request Forgery (CSRF) vulnerability in multipl | Feb 3, 2026 | 6.5 | 20 | NO | NO |
CVE-2026-24665MEDIUM The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a stored Cross-Site Scripting (XSS) vulnerability allows aut | Feb 3, 2026 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gunet.
Media articles that mention a CVE ID that affects a product developed by Gunet — matched by CVE ID, not by vendor name.